Anonymous
2026-09-14 05:47:28
(1 hour ago)
34.34.91.125 - - [14/Sep/2026:05:47:12 +0000] "GET /.git/config HTTP/1.1" 502 552 "-" "Mozilla/5.0 ( ...
show more
34.34.91.125 - - [14/Sep/2026:05:47:12 +0000] "GET /.git/config HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.34.91.125 - - [14/Sep/2026:05:47:19 +0000] "GET /.env HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.34.91.125 - - [14/Sep/2026:05:47:22 +0000] "GET /.env.local HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.34.91.125 - - [14/Sep/2026:05:47:25 +0000] "GET /.env.production HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.34.91.125 - - [14/Sep/2026:05:47:28 +0000] "GET /.env.staging HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Port Scan
Brute-Force
🇨🇦
zXero
2026-09-14 03:02:58
(3 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
🇺🇸
gamabe
2026-09-14 02:55:03
(3 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
🇮🇹
VHosting
2026-09-14 02:40:08
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-14 01:25:44
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-14 01:02:47
(5 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-14 00:10:37
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-14 00:10 UTC
show less
Hacking
Web App Attack
🇺🇸
jormaster3k
2026-09-13 22:28:58
(8 hours ago)
Attack against Apache (too many 404s)
Web App Attack
🇳🇱
Site.eu
2026-09-13 22:23:54
(8 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
Charlesiv
2026-09-13 20:03:31
(10 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-13T18:15:07Z
Ray ID: a3a922ae6a730b88
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
🇪🇸
Francisco Vallejo
2026-09-13 19:22:21
(11 hours ago)
[Sun Sep 13 21:22:20.685513 2026] [authz_core:error] [pid 1524022:tid 126979011495616] [client 34.34 ...
show more
[Sun Sep 13 21:22:20.685513 2026] [authz_core:error] [pid 1524022:tid 126979011495616] [client 34.34.91.125:40706] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Sun Sep 13 21:22:20.726377 2026] [authz_core:error] [pid 1524022:tid 126978459940544] [client 34.34.91.125:40706] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Sun Sep 13 21:22:20.913891 2026] [authz_core:error] [pid 1524022:tid 126979028281024] [client 34.34.91.125:40706] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Sun Sep 13 21:22:20.968112 2026] [authz_core:error] [pid 1524022:tid 126978977924800] [client 34.34.91.125:40706] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Sun Sep 13 21:22:21.052308 2026] [authz_core:error] [pid 1524022:tid 126977948247744] [client 34.34.91.125:40706] AH01630: client denied by server configuration: proxy:http://giedi:3000/.git/config
...
show less
Brute-Force
SSH
🇫🇮
as211431.net
2026-09-13 19:12:24
(11 hours ago)
Triggered Cloudflare WAF (linkMaze) from NL.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from NL.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
daveoctober
2026-09-13 17:54:11
(12 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-13 13:27:01
(17 hours ago)
csagent: score 21.0: 404 noise floor x4, secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇨🇭
dalslab ltd
2026-09-13 04:23:42
(1 day ago)
[13/Sep/2026:06:23:18 +0200] - 405 405 - POST https music.dalslab.com "/" [Client 34.34.91.125] [Len ...
show more
[13/Sep/2026:06:23:18 +0200] - 405 405 - POST https music.dalslab.com "/" [Client 34.34.91.125] [Length 0] [Gzip -] [Sent-to 10.1.1.23] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[13/Sep/2026:06:23:27 +0200] - 404 404 - GET https music.dalslab.com "/app/.env" [Client 34.34.91.125] [Length 43] [Gzip -] [Sent-to 10.1.1.23] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[13/Sep/2026:06:23:28 +0200] - 404 404 - GET https music.dalslab.com "/api/.env" [Client 34.34.91.125] [Length 43] [Gzip -] [Sent-to 10.1.1.23] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[13/Sep/2026:06:23:41 +0200] - 404 404 - GET https music.dalslab.com "/api/v1/.env" [Client 34.34.91.125] [Length 43] [Gzip -] [Sent-to 10.1.1.23] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack